Show HN: Get a list of your Amazon purchases and see what you can sell them for
shelfflip.com
shelfflip.com
For some reason, the "Norton Secured" badge makes me less likely to trust the site and looking at the inline, not very well written Javascript gives me even less confident that the guys behind this site have the technical chops to keep my data secure.
A possible solution:
There's a "Login with Amazon" service that may be what the developer needs to be using: http://login.amazon.com/
Because it seemed out of place, it felt like it was an obvious tactic to bootstrap trust where there wasn't any. A better icon (for me) would have been a badge from your SSL provider, or even just some well designed lock icon.
It seems like they need to do a better job of education users about that. I don't think they have a pure "Symantec SSL" batch anymore.
disc: not implying you would disagree with any of the above.
<form id="add_products_form" name="add_products_form" onsubmit="connect_amazon2(); return false;" method="post" enctype="multipart/form-data" _lpchecked="1">
This is from chrome developer tools, network tab
Also, would you say chrome developer tools is the lightest/most accessible way for the general public to inspect for such a thing?
EDIT: TY, schrodinger. That turned out to be a tab in Dev Tools that I just hadn't dug into before. No need to install anything!
The connect_amazon2() must be making the GET request.
It's actually using GET to their server and something unknown to Amazon (that would most likely be server to server and not accessible over Javascript).
Although the method on the form is POST, it has an onsubmit handler which calls the connect_amazon2() JS function (which makes a GET AJAX request on line 311) and then returns false, preventing the form from being submitted.
Yes, the Chrome Dev Tools are probably the easiest way to take a look at this type of information. I actually used Safari, but Chrome's tools are much easier to use.
As well as on Amazon's logs, which aren't meant to hold customers' passwords. This is bad, bad, bad (interesting idea though).
To do that as well, it needs to be an extension and it should also monitor whenever you buy something. If there is a concern that purchases might happen when on another computer, you could allow the user to enter their password into the extension so that the extension can monitor things for you in the background. While users don't have a guarantee that the extension is using the password securely, at least it is possible for the source code to be inspected.
Gaining this trust, though, will probably not be easy. One advantage a site like Mint has is that they have so much content and so many partnerships that it is clear they are not a scam, have enough at stake to not misuse my information, and probably have the resources to keep it safe. A site like yours, however, could easily have been cobbled together in a number of hours by a scammer. (I don't mean this as a criticism -- I actually like your site. It just doesn't have anything on it to suggest that you are the sort of business I can trust with my passwords.)
There is no way I'm giving out my Amazon creds which also house AWS, Amazon Payments, Amazon Sellercentral, etc...
Much more cumbersome for users but I see a report option where you can generate .csv's of every item you ordered, maybe those could be uploaded to your service, but unfortunately if I can't use this service without handing over my creds I'm not going to use it.
You claim to not have access to credit card information or being able to order something, but I already have to trust you to believe that claim. Also, Amazon could change their policies at any time -- after all you have credentials, Amazon could decide to trust you.
You will find that both are not possible
I am not foolish enough to believe that my attackers are no more clever than myself. So whether I can extract my credit card from my account is not useful.
I can imagine it would be much, much easier for such social-engineering replacement fraud to happen if someone actually had access to your account with all of its order number data in the clear.
They would be restricted to just reordering things you've already ordered in the past, but I imagine that it doesn't take too many incidents on your account (especially if they figure out you've given your password away freely to a third party) before Amazon shuts you down, with all of the pain associated with that if you're a prime/kindle/etc user.
This seems like a cool service, but there's no way in hell I'm giving anyone my Amazon password for any purpose.
[0] http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall...
In order to trust you with credentials, it is necessary that you show you have thought everything through. The user needs to know that you will not leak credentials. It's a very high bar. You have simply failed to clear the bar.
http://www.amazon.com/gp/help/customer/display.html?nodeId=2...
No. Asking people to give out their passwords is fucking horrific. You can't do anything with Amazon, but bad_guy could do something with $other_service and you're just encouraging people to be lazy with passwords.
It's hard enough to get people to choose good passwords and not store them in stupid ways.
The cost efficiency is terrible of course, but what do they care.
- My credit card details (multiple)
- Shipping / billing addresses
- My private order history 5+ years
- Access to all my AWS instances
- Amazon Cloud Drive data
- And I'm probably forgetting a few...
With that being said, even services like Mint.com require handing over your bank's password to them even today. It's really not a good practice even if they are stored securely.
"Your Amazon.com password has been changed"
This is an important message from Amazon.com.
As a precaution, we've reset your Amazon.com password because you may have been subject to a "phishing" scam.
Here's how phishing works:
A scam artist sends an e-mail, which is designed to look like it came from a reputable company such as a bank, financial institution, or retailer like Amazon.com, but is in fact a forgery. These e-mails direct you to a website that looks remarkably similar to the reputable company's website, where you are asked to provide account information such as your e-mail address and password. Since that web site is actually controlled by the phisher, they get the information you entered.
Go to amazon.com/phish to read more about ways to protect yourself from phishing.
To regain access to your Amazon customer account:
1. Go to Amazon.com and click the "Your Account" link at the top of our website.
2. Click the link that says "Forgot your password?"
3. Follow the instructions to set a new password for your account.
Please choose a new password and do not use the same password you used with us previously.
Thank you for your interest in Amazon.com.
Got the same exact email...
You should not be collecting peoples' usernames and passwords, being a software engineer aware of the consequences, regardless of whether users are willing to give them up.
There are so many things that can go wrong, even if you've got the best of intentions.
Also these prices make no sense for when I search items directly. How can a flawless Nexus 7 2013 be worth only $70? Where can I buy them all?
It's worth $70 to them. They are buying to resell, and they can pay a lower price for the convenience of getting the item from your house and paying you instantly.
One can always sell it on eBay/craigslist and get a bigger price, but you'll have to deal with buyers, scammers, shipping, etc. It boils down to how much your time is worth and/or how fast you need the money.
You HAVE to find a better way to do this. People are becoming increasingly aware of the risks of this kind of behavior on malicious sites, and potential users will walk away out of paranoia.
It's a great idea, if you can find another way.
I have lots of things I would like to sell and declutter, but none of them are from Amazon.
When I got the "Are you sure?" message, I started thinking that the site was specifically crafted to show how easy it is to get people to give passwords to a "reputable-looking" third party.
I expected to get some sort of congratulatory message after saying no, like "You're smart enough to not give us your password!" When I didn't get that, I came back to the HN comments, expecting to see an explanation from OP about this proof of concept.
Then I see it's supposed to be a real site. Well then.
@everyone: Want us to email you as soon as we have a password-free way to import your purchases? (for example through csv import)
Shoot me an email to christian@shelfflip.com (subject: "shelfflip passwordfree")
Scanning 44 other book-buying sites, only 3 are buying that book and the price is between $0.12 and $3.97
http://www.amazon.com/gp/help/customer/display.html?nodeId=2...
I know it puts some burden on the customer, but as a fallback, it's better than losing them.
I got frustrated with the process of listing / selling items on Amazon (I imagine a lot of it could be automated), and looked around for a service like this (and then added it to my 'side-project' idea list).
I'll give it a shot next time I get rid of stuff.
For example: Apple MacBook Pro ME864LL/A 13.3-Inch Laptop with Retina Display (NEWEST VERSION) $382.32
It's a compelling business idea, and I understand there's a need to generate a profit, yet the math seems a little off.
If this were Reddit, this is the point where I would attach a hilarious GIF of some animal running away with the text "NOPE" all over it.